Privacy Policy

1. Scope and applicability

This Privacy Policy applies to all personal data processed by Vansera in connection with:

It does not apply to: the in-restaurant experience at any Client Establishment, third-party websites we link to, or personal data you provide directly to a Client Establishment by walking in, calling a non-Vansera number, or messaging a non-Vansera WhatsApp number. Those are governed by the Client Establishment's own privacy practices.

2. Definitions

We use defined terms from the DPDP Act so that this notice is interpretable in legal proceedings. For clarity:

3. Who we are — identity of the Data Fiduciary

Throughout this notice, "Vansera", "we", "us" and "our" refer to the entity above. References to "you" or "the Data Principal" mean the individual whose personal data is being processed.

4. Categories of personal data we process

We have organised every category of personal data we touch into a single table. We do not process any category not listed below. Where the source column says "you", the data came directly from the Data Principal; where it says "Client Establishment", the data was provided by the cafe (for example when they imported an existing reservation book during onboarding); where it says "system", the data was generated by Vansera's infrastructure.

We do not collect, by any channel: Aadhaar or other government identifiers; PAN; voter ID; biometric templates; voice prints used for identification; financial account numbers, credit card numbers, CVVs or UPI handles; location data of any kind (GPS, Wi-Fi or cell-tower); device contact lists, photos or calendars; health, medical or insurance information; sexual orientation or sex life; political opinions, religious beliefs, caste or community; criminal records or pendency of proceedings; trade-union membership; or any data of any individual we have actual knowledge is below 18 years of age. If you transmit any such information to us inadvertently (for example by reading a card number aloud over the phone), we will redact it from transcripts upon detection and will not retain it.

5. How we collect personal data (channels of collection)

6. Purposes for which we process your personal data

We process personal data only for the purposes set out below, and only to the extent necessary for each purpose:

7. Lawful basis for processing under the DPDP Act

The Digital Personal Data Protection Act, 2023 permits processing on the basis of (a) the Data Principal's consent or (b) certain "legitimate uses" enumerated in Section 7. We rely on each as follows:

We do not rely on any deemed-consent, public-interest or implied-consent ground other than those enumerated above.

8. Sub-processors, recipients and third-party service providers

The following third parties process personal data on Vansera's instructions in order to deliver the Service. Each is bound by its own data-protection commitments. We have selected each on the basis of published documentation of contractual and technical safeguards. We do not sell, license, rent or otherwise commercialise personal data to any party.

Where we add or replace a sub-processor in a way that materially changes how your personal data is processed, we will update this Section 8 and post a notice on the home page at least thirty (30) days before the change takes effect, unless the change is required by law or by a security incident in which case we will update as soon as practicable.

9. Cross-border transfers of personal data

Some sub-processors listed in Section 8 are located outside India. Under Section 16 of the DPDP Act, transfers of personal data to a country outside India are permitted unless the Central Government, by notification, restricts such transfer to a specific country. As of the effective date of this notice, the Central Government has not issued any such notification restricting transfers to the United States, where most of our sub-processors are based.

For each cross-border transfer, we apply the following safeguards:

10. Retention of personal data and method of deletion

Retention periods are maxima. We may delete sooner where legitimate business need has ended. Where you exercise your right to erasure under Section 12, we will delete within thirty (30) days of verifying your identity, subject only to retention required by law (for example, for tax-record retention or in response to a litigation hold).

11. Security — technical and organisational measures

We implement the following technical and organisational measures, which we believe satisfy the "reasonable security practices and procedures" required under Section 43A of the IT Act and the SPDI Rules:

No technical or organisational measure can eliminate the risk of a personal-data breach. By using the Service you acknowledge that the controls listed above are reasonable, not absolute.

12. Personal-data breaches — notification commitment

In the event of a personal-data breach as defined in the DPDP Act, we will:

13. Your rights as a Data Principal under the DPDP Act

The DPDP Act confers the following rights on you. We honour each without charge and without conditioning your continued use of the Service on whether you have exercised them.

How to exercise a right. Email the Grievance Officer at contact@vansera.in with the subject line Data Request — [your phone number]. To enable us to verify that you are the Data Principal (and not a third party trying to obtain your data), we may ask you to confirm a one-time code we send to the phone number on file. We will respond within thirty (30) days of receipt, or earlier where the law requires it. If your request is manifestly unfounded or excessive, we may decline it with reasons or charge a reasonable fee, as permitted by the DPDP Act and the rules made under it.

14. Grievance Officer

If, after escalation to the Grievance Officer, your grievance remains unresolved, you may approach the Data Protection Board of India once it is constituted and operational under the DPDP Act, 2023. You may also have a remedy under the Information Technology Act, 2000, the Consumer Protection Act, 2019, or in the civil courts of competent jurisdiction.

15. Automated decision-making and AI disclosure

The Service uses an automated AI system to take and manage your reservation. There is no human intervention in the moment-to-moment conversation. The AI is configured to disclose, when asked or at the start of the interaction, that it is an automated assistant.

We do not use the conversation to make any decision that produces legal effects concerning you or that significantly affects you in a similar way; the AI's decisions are limited to whether a particular booking can be accepted given availability, and whether the conversation can be advanced to the next step. You retain the right to decline interaction with the AI at any time, including by ending the call, replying STOP on WhatsApp, or asking to be transferred to a human (where the relevant Client Establishment has enabled call forwarding for its number).

We do not generate or store voice biometric profiles, voice prints, speaker-identification embeddings or any other biometric template of your voice. The audio of your speech is converted to text in transit and the audio itself is not retained.

16. Children

The Service is intended for adults making restaurant reservations. We do not knowingly process the personal data of any individual we have actual knowledge is below 18 years of age. Where you make a reservation that includes minors as guests, we process only the headcount and any allergy or dietary information you supply; we do not collect minors' names, contact details or any other identifier.

If you become aware that a person below 18 has provided personal data to the Service, please write to the Grievance Officer named in Section 14 and we will promptly delete such data and any related records.

17. Marketing communications and TRAI compliance

We send only transactional and service messages: reservation confirmations, reminders, modifications and feedback requests on behalf of the Client Establishment. We do not send promotional or advertising messages to End Users. Should we ever introduce promotional messaging in future, it will be on an explicit opt-in basis and in compliance with the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (TRAI TCCCPR), including registration with a DLT platform where required.

You may stop all messages from a Vansera-operated WhatsApp number at any time by replying STOP to that number; we will cease sending further messages within twenty-four (24) hours.

18. Cookies and similar technologies

The vansera.in marketing website uses only essential first-party cookies necessary to operate the administrator session and to remember consent state where applicable. We do not run third-party analytics, advertising pixels, social-media share trackers or fingerprinting libraries on this domain.

19. Lawful interception, court orders and government requests

We will disclose personal data to law-enforcement, regulatory or judicial authorities only where compelled by a validly issued summons, court order, warrant or other legal process under Indian law. Where law permits us to do so, we will notify the affected Data Principal and any affected Client Establishment of the request before disclosure, so that they may pursue any remedies available to them.

20. Independent retention by sub-processors

Some sub-processors retain limited operational metadata about their interaction with us (for example, Twilio retains message-delivery logs for its own audit purposes). Such retention is governed by the sub-processor's own privacy policy. You may obtain a current list of the sub-processors' published privacy commitments from us on request.

21. Changes to this Privacy Policy

We may revise this Policy from time to time. Material revisions — including any change to the categories of data collected, the purposes of processing, retention periods, the list of sub-processors, or the categories of recipients — will be posted on this page with a revised "Effective" date, and where reasonably possible we will provide thirty (30) days' advance notice via the home page. Non-material revisions (typographical, clarifying or formatting) take effect immediately.

Your continued use of the Service after a revision takes effect constitutes acceptance of the revised Policy. Prior versions are available on request.

22. Compliance with other Indian laws

In addition to the DPDP Act, our practices are designed to comply with:

23. Contact

For any privacy-related question, write to contact@vansera.in. For commercial, sales and administrative matters, see the home page. For complaints, please first contact the Grievance Officer in Section 14 above.